---
title: "Api Auth Verify Device"
method: POST
path: "/api/auth/verify"
tags: ["Infrastructure"]
---

# Api Auth Verify Device

`POST /api/auth/verify`

Verify a device code by entering the user_code shown in the CLI.

Called from the web dashboard after the user logs in and enters their code.
Requires a valid session (cookie or bearer token) so the CLI token can be
tied to the authenticated user.  Falls back to creating an anonymous session
when no user context is available (e.g. first-time sign-up via device flow).

## Request body

- DeviceVerifyRequest
  - `user_code` string, required

## Response `200`

Successful Response

- unknown

## Other responses

- `422` — Validation Error

## Changes

- **2026-04-05** `f2668775365c` — 1 info
  - endpoint added
- **2026-04-03** `aca6ce6b2785` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/aabiro/apis/xcelsior/changes/api/auth/verify/post.md)

---

[API](https://skmtc.dev/aabiro/apis/xcelsior.md) · [All operations](https://skmtc.dev/aabiro/apis/xcelsior/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/aabiro/xcelsior/revisions/f2668775365c/schema)
